Security groups vs. a traditional firewall: what's the difference
Quick answer
A security group is filtering rules attached directly to one server or a set of servers, managed at the cloud platform level. A traditional network firewall sits in front of a whole network segment instead of a single instance. Both usually work on the same underlying idea, a stateful rule set that tracks connections and automatically allows return traffic, but they operate at a different layer of the network.
The term "security group" shows up across most major cloud platforms to describe rules that travel with a specific server rather than sitting in front of a whole network. It's worth understanding the distinction even if you never touch a platform that uses that exact name, because the underlying idea, filtering attached to an instance versus filtering attached to a network boundary, comes up under other names too.
What a security group is
A security group is a set of allow rules that a cloud platform lets you attach directly to a server, or to a group of servers that share the same role. Instead of routing traffic through a separate appliance, the platform enforces the rules at the point where the instance's network interface meets the rest of the network. Add a server to a security group, and its inbound and outbound traffic gets filtered according to that group's rules, no separate device to configure.
Security groups are typically stateful by default. If a rule allows an outbound connection, the platform automatically permits the matching return traffic back in, without needing a separate inbound rule for it. That's a deliberate simplification: you write the rule for the direction that matters to you, and the platform handles the reply traffic on its own.
What a traditional firewall is
A traditional network firewall, sometimes called a perimeter firewall, sits in front of a whole network segment rather than being attached to one instance. Every server behind it shares the same gateway and the same set of rules, unless you carve out more specific exceptions. Worldstream's own Firewall product in Portal is this kind of shared, per-region gateway: you create one firewall per region and attach your internal networks to it, and its rule sets live on separate NAT Rules and Firewall Rules tabs. See Firewall basics in Portal for how that's set up.
Architecturally, that's the core difference. A security group is instance-level and travels with the server. A perimeter firewall is network-level and applies uniformly to everything behind it.
Stateful vs. stateless: the concept behind both
Whether you're looking at a security group or a perimeter firewall, the rules underneath tend to work one of two ways:
- Stateful: the firewall tracks active connections. Allow a connection out, and the return traffic is automatically permitted back in, no matching inbound rule required. This is the more common default on modern platforms because it's simpler to reason about, you write a rule per direction of traffic you actually want to initiate.
- Stateless: every packet is evaluated on its own, with no memory of what came before. To let a connection work in both directions, you need explicit rules for the outbound leg and the inbound leg separately. This is less common as a default today but still shows up in some lower-level network access control lists.
Most security groups and most modern perimeter firewalls default to stateful behaviour. The stateful/stateless distinction is a separate axis from the instance-level/network-level distinction covered above, a firewall can be perimeter-level and still be stateful, and in practice most are.
Why this distinction matters
Understanding the difference helps when you're reading documentation from different platforms or moving workloads between them. A platform that talks about "security groups" is describing rules that live with the instance. A platform that talks about a "firewall" in the traditional sense is usually describing something that sits in front of a network segment. Neither is inherently better, they solve filtering at different layers, and many setups use both: a perimeter firewall for broad network boundaries, plus finer-grained rules closer to individual workloads.